Overview 58 indicators
No published description. This group is tracked by Maltrail from vendor reporting but is not named in MITRE ATT&CK, so there is no curated profile to show.
| domain | 58 | PKPLUG-domain.txt |
Principal sources 6 reports
Ranked by how many of this actor's indicators each report brought in.
- 55unit42.paloaltonetworks.com/pkplug_chinese_cyber_espionage_group_at…
- 55pan-unit42.github.io/playbook_viewer/?pb=pkplug
- 3unit42.paloaltonetworks.com/unsigned-dlls
- 3unit42.paloaltonetworks.com/stately-taurus-attacks-se-asian-governm…
- 3otx.alienvault.com/pulse/6511d6fd63ecbfd938c3580f
- 3community.emergingthreats.net/t/ruleset-update-summary-2023-09-22-v10…
Related groups 2
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 58 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
unit42.paloaltonetworks.com/unsigned-dlls · unit42.paloaltonetworks.com/stately-taurus-attacks-se-asian-governm… · otx.alienvault.com/pulse/6511d6fd63ecbfd938c3580f · community.emergingthreats.net/t/ruleset-update-summary-2023-09-22-v10…
uvfr4ep.com -
unit42.paloaltonetworks.com/unsigned-dlls · unit42.paloaltonetworks.com/stately-taurus-attacks-se-asian-governm… · otx.alienvault.com/pulse/6511d6fd63ecbfd938c3580f · community.emergingthreats.net/t/ruleset-update-summary-2023-09-22-v10…
feed-5613.coderformylife.info uvfr43p.com -
unit42.paloaltonetworks.com/pkplug_chinese_cyber_espionage_group_at… · pan-unit42.github.io/playbook_viewer/?pb=pkplug
hwmt10.w3.ezua.com imw100pass.imwork.net jackhex.md5c.com lzsps.ml news.tibetgroupworks.com nslookupdns.com ppt.bodologetee.com sm.umtt.com tibetgroupworks.com uyghurapps.net web.microsoftdefence.com web.outlooksysm.net workwifi.andphocen.com yl.andphocen.com -
unit42.paloaltonetworks.com/pkplug_chinese_cyber_espionage_group_at… · pan-unit42.github.io/playbook_viewer/?pb=pkplug
3w.tcpdo.net adminloader.com adminsysteminfo.com andphocen.com app.newfacebk.com cdncool.com csip6.biz dns.cdncool.com honor2020.ga info.adminsysteminfo.com lala513.gicp.net linkdatax.com mail.queryurl.com md.sony36.com md5c.net netvovo.windowsnetwork.org newfacebk.com re.queryurl.com sony36.com tcpdo.net up.outhmail.com update.newfacebk.com update.queryurl.com update.tcpdo.net w3.changeip.org w3.ezua.com windowsnetwork.org work.andphocen.com www3.mefound.com www5.zyns.com -
unit42.paloaltonetworks.com/pkplug_chinese_cyber_espionage_group_at… · pan-unit42.github.io/playbook_viewer/?pb=pkplug
admin.nslookupdns.com appupdatemoremagic.com gooledriveservice.com jackhex.md5c.net logitechwkgame.com microsoftdefence.com microsoftserve.com mxdnsv6.com outhmail.com queryurl.com webserver.servehttp.com
Further reading 6
- otx.alienvault.com/pulse/6511d6fd63ecbfd938c3580f
- unit42.paloaltonetworks.com/unsigned-dlls
- unit42.paloaltonetworks.com/pkplug_chinese_cyber_espionage_group_at…
- pan-unit42.github.io/playbook_viewer/?pb=pkplug
- unit42.paloaltonetworks.com/stately-taurus-attacks-se-asian-governm…
- community.emergingthreats.net/t/ruleset-update-summary-2023-09-22-v10…